I haven’t really followed the whole thread, but I’ve been seeing it for months that I recall, definitely a waste of bandwidth, and probably should be solved to some extent.
Looking at his logs, the headers are only for a CVD, so he’s not trying updates.
Trying 104.16.186.138...
Connected to database.clamav.net.cdn.cloudflare.net.
Escape character is '^]'.
GET /daily-25195.cdiff HTTP/1.1
?????o??_}??/~?uЯ?|??~?f?l??Ox????????~??????O6????/??????_?????>??Ϸ_????7?~??̯???ߢ?????ӏ~???B??{}~?[????A???7????ņ?>???
You don’t get those nice header parts to the file, so you wouldn’t know the last update as it’s apart of the file itself. Looking at manager.c on freshclam, he should have been posting something like: "^getfile: %s not found on %s (IP: %s)\n" which gets posted to the logs when the file doesn’t exist.
I’m not positive on this so Micah can chime in, but I do believe you get the cdiff files from the DNS TXT somehow.
If anything it’s a good lesson on how exactly freshclam works.
Sincerely,
Eric Tykwinski